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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Module TOR SECRETHICOMB-ENGEORA— 1 of 20 
Introduction 


FRAME ID: 7010 
(U) Module 6 


(U) The Technical Work Role 


REST FRAME IE: 7CET (U) This module will enable you to: 


¢ ~FSHSIANF} Identify the various technical roles that support the BR and PR/TT Bulk 
Metadata Programs 
(U) Identify the responsibilities of each of the technical roles 
ALT TAG: (U) Recognize key points of the compliance certification process for mission 
systems and data flows 
(FS4S/4NF) Practice applying BR and PRATT authorities in real-life scenarios 
applicable to technical personnel 


GRAPHIC/AV: 


FFSHSIYNF) (OGC Attorney): During this part of our trip, we discuss several topics of particular interest to those of you In technical roles, or supervising 
staff in a technical role, supporting the BR and PR/TT Bulk Metadata Programs. It js impoitant for you to remember that the essential support you provide 
enables all of the roles to perform their BR- and PR/TT-related work in compliance with applicable legal documents and relevant authorities. As we 
discussed in Module 5, because of this great responsibility, technical personnel have been given tremendous access to touch the data in order to make jt 
available and usable for the analysts. 


OS4S/4N6) (Technical Character): In this module we are going to discuss the authorizations, roles, and responsibilities of the Technical Personnel. This 
module will enable you to: 
« = <FGHSHAS) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 
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ə (U) Identify the responsibilities of each of the technical roles 
+ (U) Recognize key points of the compliance certification process for mission systems and data flows 
« (FSHSIHNP Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Two General Categories of TOP 2 of 20 
Technical Support Roles SEGREF#HEO mINTFANOFORN- 


FRAME ID: 7020 
(U) Two General Categories of Technical Support Roles 


NEXT FRAME ID: 7030 A 
(U) Collection and Metadata Bi 


BACK FRAME ID: 7010 (U) Storage, Presentation, and Maintenance of the Metadata 
ALT TAG: 


GRAPHIC/AV: 
(U) Image of Technical Character sitting at 
a desk 


: FSHSIHNE (Technical Character): In Module 5, we explained there are two major areas where technical support is provided for the BR and PR/TT Bulk 
Metadata Programs. The first is the group of technical personnel who are responsible for the collection and metadata pmm process. The second is the 
group responsible for storage, presentation, and maintenance of the BR and PR/TT metadata. In the next few screens, we will describe in more detail these 
two main areas of responsibility. 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Collection and Metadata —FOR-SECRER COMMITEE OEORS 3 of 20 


| upport 


FRAME ID: 7030 


(U) Collection and Metadata Extraction Support 


(U) Collection and Metadata e 


NEXT FRAME ID: 7040 


(U) Mission Capabilities 


(U//F OUO)-(Technical Character): Let’s examine more closely the work roles responsib lleci ad metadatal wmeeeees This 
and Mission 


category of technical staff currently includes the technical professionals in NSA' 
Capabilities staff within the Technology Directorate (TD) organizations. As we proceed through this module you will find out more about the roles in each of 


these three organizations. 


+CFSHSIANF) Note that in addition to these key roles, there are other technical roles that are important to the implementation of these programs. These roles 
include individuals involved in the acquisition, processing, presentation, storage, retention, and support to operations which are authorized under the BR 


and PR/TT Orders. 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
Shia lection and —FOP-SEGREFIEE MINTFINGFORN 4 of 20 
Metadata Support from 


FRAME ID: 7040 


NEXT FRAME ID: 7050 


BACK FRAME ID: 7030 
ALT TAG: (u/Fouo) Ml [Logo 
GRAPHIC/A\. se 


S/SU/REL) s responsible for 


og and info be 


info is displayed 
logo_sm.png 


~<ESHSHANBS Some of the rules that apply tol 
e Acquire datal authorized by the FISC 


e Identify all m 


. lis promptly destroyed 
e Changes to systems require approval by the Chief of S3 


(TS#SINF) (Technical Character): The first Technical Work Role that supports the collection and metadata brocesses is 
is 


(TS//SI//NE) For BR. the IE role is similar in that Ill 


Al x 
T re 
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Ihat have been authorized by the FISC 
All of the metadata is identifiable as BR or PR/TT data 


Data which does not fall within FISC specified requirements regarding rr a must be 
promptly destroyed 


= 
Changes to systems under i urview are approved by the Chief of S3 before implementation 


CPSASIANF}The staff in ill rarely come in contact with human intelligible BR and/or PR/TT metadata. Scroll over T 
to find out more about | 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
lection and Metacata | FOR-SECRETYCOMINFHNOFORN 5 of 20 
Isup port from 


FRAME ID: 7050 


(U) Collection and Metadata 


NEXT FRAME ID: 7060 


BACK FRAME ID: 7040 (TS/SL//NF) 


ALT TAG: (U) I PE ogo 
GRAPHIC/A) fmm 


=, 


ae wh ae info is 
E <0 jpg a 


TESSEN Some of the roles that 


e Provide reasonable assurance that all 
compliance with FISC Orders 
e Validate that only properly) 


brganization, and to a lesser extent the Mission Capabilities organization, supports the 


+ESHSHNFE: Some of the roles that include: 
a Provide reasonable assurance that all re in compliance with the 
FISC Orders. T 
+ Validate that only properly EEEE metadata is forwarded to the Po R analytic use. 
Sa 


y + 
k T 
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“FOP-SEGCRETISHNOEORN- 


These individuals have direct and continual access and interaction with both || . Scroll over the 


logo to find out more about 


Scroll over text box for BE ogo: 
Pop-up screen for W logo: (G#StHfREL) The IEEE [Sranch analyzes new digital communication] land researches new digital 
network communications technologies to pro quired for their exploitation. 

—FOR SEGCREHSHNOFOR— 


Page § of 30 


DATE/PREPARER: SLS Topic Page Classification Screen Number 
on and Metadata FGP-SESRETHFCCMIAEHANGFORN 6 of 20 
>upport from TD 

JHO 


(U) Collection and Metadata E: upp ort 
(U) Collection and Metadata l nn 


FRAME ID: 7060 


NEXT FRAME ID: 7070 


BACK FRAME ID: 7050 -CESYSHANF) Mission Capz )iliti 


ALT TAG: (U) Mission Capabilities Logo staff integrates the PR/TTH 


(U) Mission Capabilities 


Sw ————— 
td-logo-small.gif (or td-logo-med.gif) 


fs promptly destroyed 


: Finally the Mission Capabilities, or TD, staff support the collection and metadata Il [processes by integrating the 


OE Some of the rules that apply to Mission Capabilities staff within the as Directorate (TD) are to provide reasonable assurance that: 


All of the metadata remains identifiable as PR/TT data 
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{FSHSHNA This staff will rarely come in contact with human intelligible PR/TT metadata. Scroll over the logo to find out more about Mission Capabilities. 


wh SS) SAL MIA IA SOI 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) TOR SECRETICOMHPHANGFORAR- 7 of 20 
Knowledge 
Check 1 
FRAME ID: 7070 (U) Knowledge Check 1 
(U) Match the organization to its corresponding roles and responsibilities: 


1. (TSHSI/NE) Staff in is responsible for developina the 


NEXT FRAME ID: 7080 


BACK FRAME ID: 7060 
ALT TAG: 


GRAPHIC/AV: is responsible for integrating the PRITTH 
(U) NOTE: Use a matching format Hincluding conducting related testing prior to system 


(responsibilities listed on one 

side and the organizations listed 

on the other side) so that the 

user matches up the 

organization to the appropriate (U) Homeland Mission Coordinators 
responsibilities. 


3. FSHSHANF} Staff in is responsible for| 


a) (U) Mission Capabilities 
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Question 2. (TS#SI//NF) Staff in Mission Capabilities is responsible for integrating the a 


Question 3. (TS#SI/INF) Staff in 


PER ECR SEN OROR A 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Storage, Presentation, and —FOP-SEGREFIGOMIV- ANGE ORN— 8 of 20 
Maintenance of the Metadata 


(U) Storage, Presentation, and Maintenance of the Metadata 


FRAME ID: 7080 


(U) Storage, Presentation, and Maintenance of the Metadata 


NEXT FRAME ID: 7090 


(U) Mission Capabilities 
BACK FRAME ID: 7070 l 


ALT TAG: 


GRAPHIC/AV: 

(U) Have the Storage, Presentation, and 
Maintenance of the Metadata box expand 
to reveal the Mission Capabilities and 


{FS#SHNF (Technical Character): Now let's discuss the work roles responsible for the storage, presentation, and maipi ie BR and PRATT 
metadata. This category of technical staff currently includes the technical professionals in Mission Capabilities and 


—TOP-SEGCRETHSHNOFORM— 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Storage, Presentation, and TOP 9 of 20 
Maintenance of the Metadata by TD —SECRETFECMINTINOFORN— 


FRAME ID: 7090 
(U) Storage, Presentation, and Maintenance of the Metadata 


(U) Storage, Presentation, and Maintenance of the Metadata 


NEXT FRAME ID: 7100 


(FS#SHNF) Mission Capabilities is 


responsible for: 
BACK FRAME ID: 7080 (U) Mission | (O Mission Capabilities | e Developing, maintaining, and operating 
i repositories that store and present BR and 


ALT TAG: (U) Mission Capabilities Logo PR/TT metadata 


GRAPHIC/AV: ° 
(U) Have the TD lg 

and grey out the | 

boxes while the Mission Capabilities info is 


displayed 
td-logo-small.gif (or td-logo-med.gif) 
-CESASTANF Some of the rules that apply to Mission Capabilities: 
Metadata must be maintained in secure NSA repositories 
Data must be identifiable as BR or PR/TT 


Restrict intelligence erea queries to RAS-approved identities (e.g. the EAR) 
Ensure intelligence analysis queries remain within authorized number of hops 
Create auditable records of all intelligence analysis queries 

Destroy all metadata before the end of the five year authorized retention period (no 
exceptions!) 

Changes to systems must be certified by the TD Compliance Office before 
implementation 

Automated queries are prohibited without approval 


~FOP-SECRETASHANOFORE 
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+FSHSW/NE\ (Technical Character): You will recall that Mission Capabilities supports collection and metadata I Hand other branches of Mission 
Capabilities support storage, presentation, and maintenance of the metadata. For the latter. the staff is typically database management and user interface 
professionals who are responsible for developing, maintaining, and operating the MA store and present BR and PR/TT metadata, as well as 


CFSHSHAMF) Some of the rules that apply to Mission Capabilities include: 
e Metadata must be maintained in secure NSA repositories 


e Data items must be identifiable as BR or PR/TT metadata 
e Implement technical controls to prevent unauthorized access 


e Implement technical controls to restrict intelligence analysis queries to RAS-approved identifiers (e.g. the EAR) 

e Implement technical controls to provide reasonable assurance that the results of intelligence analysis queries remain within the authorized number 
of hops 

e Create auditable records of all intelligence analysis queries 


Destroy all metadata before the end of the five year authorized retention period (no exceptions for backup data) 


+FSHSHANE) This staff will come in contact with human intelligible BR and PR/TT metadata. 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Storage, Presentation, and —Tor 10 of 20 
Maintenance of the Metadata by PE —SESRETACCMINTTINOFORIT 


FRAME ID: 7100 
(U) Storage, Presentation, and Maintenance of the Metadata 


(U) Storage, Presentation, and Maintenance of the Metadata 
NEXT FRAME ID: 7110 


BACK FRAME ID: 7090 (U) Mission Capabilities (FSHSH/ND Protocol Exploitation is 


ALT TAG: (U) responsible for: 
e 


Ensuring data is normalized and is 
presented in a usable format 
e Providing support to intelligence analysts 


GRAPHIC/AV: 

(U) Have the PE logo and info box appear 
and grey out the Mission Capabilities boxes 
while the ==) info is 
displayed| 

B Logo jpg 


lerforms unique functions including: 


Normalizing” 
Reviewing data to ensure records include only data l 


Assist in ensuring that data to be presented to analysts will be in a usable format 
Providing operational support to intelligence analysts; support is limited to RAS-approved identifiers 
within the authorized number of hops 


(TS/. m- iaracter): As you recall for PK/| |. =D OV CCS SUPPOrt [cM 1.7 


BR, RPE: ssists in ensuring accurate representation and integrity of the metadata, In this context, O performs both a 


tech upporting role for intelligence analysts. Because of this dual role = M ust apply the rules governing the specific 
function it is performing at the time. When.nerformings tgchnical role, the technical rules apply which allow broader access to the data. However, when 
supporting the intelligence analyst, the staff must operate within the same rules applicable to the intelligence analyst which are more 


~FOP-SECRETHSH NOFORN- 
Page 16 of 30 


restrictive. 


(TSITSHINF) For BR | Tperiorms unique functions to include: 


Normalizing all of the disparate data formats es 
Reviewing the data to validate that the records include only datall 

Assist in ensuring that the data to be presented to the analysts will be in a usable format 

Providing operational support as necessary to intelligence analysts; support is limited to RAS-approved identifiers within the authorized number of 


hops 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
Knowledge FCP-SEGREFIECS MITE FERAT 11 of 20 
Check 2 


FRAME ID: 7110 (U) Knowledge Check 2 


4. €FSHSIHNF}Which one of these is not one of the roles and responsibilities of the technical personnel? 
a) (U/FOUO) Manipulating and validating the metadata to make it usable for intelligence analysis 
purposes 


NEXT FRAME ID: 7130 b) (FSASIHNF} Developing new tools to support querying of BR and PR/TT metadata 


c) {S4¥SHREt; Running an intelligence analysis query using a RAS-approved identifier for an analyst 
who is experiencing problems recreating their query results 


BACK FRAME ID: 7100 d) -(SHSI#REE)-Running an intelligence analysis query using a non-RAS-approved identifier for 
an analyst who is experiencing problems recreating their query results 


ALT TAG: e) (U) BothC and D 
GRAPHIC/AV: 


5. (TS/SI//NF) | o SE support to the BR program by doing the following (check all 
that apply): 


a) (U) Normalizing all of the disparate data formats eee E 

b) (U) Reviewing the data to validate that the records include data e l 

c) (U) Ensuring metadata is maintained in secure NSA repositories. 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

e) (U) Destroy all metadata before the end of the five year authorized retention period (no exceptions 
for backup data 


f) {S#SHREtŁ} Providing operational support as necessary to intelligence analysts on RAS- 
approved identifiers within the authorized number of hops 


6. (FSHSHNE} Datahase nanagement and user interface professionals in develop, 
maintain, and operate the [that store and present BR and PR/TT metadata, and develop 
algorithms/processes that prepare, optimize, and characterize the metadata for analytic utilization. 


(U) Homeland Mission Coordinators 


(U) (Technical Character): Let’s check what you remember from this topic! 


Question 4. 4S#Si#N- Correct! Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is experiencing problems 
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recreating their query results is not one of the roles and responsibilities of the technical personnel. 


~CFSHSIAN® Incorrect. The correct answer is d). Running an intelligence analysis query using a non-RAS-approved identifier for an analyst who is 
experiencing problems recreating their query results is not one of the roles and responsibilities of the technical personnel. 


| 
Question 5. ¢FSHStHANF} Correct! drovides support to the BR program by doing the following: 
a) (U) Normalizing all of the disparate data formats 
b) (U) Reviewing the data to validate that the records include data || 
d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 
f) (S#Si#REE) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 


number of hops = 
FSHSIAND Incorrect i provides support to the BR program by doing the following: 


a) (U) Normalizing all of the disparate data formats 

b) (U) Reviewing the data to validate that the records include data M2 oe 

d) (U) Assist in ensuring that the data to be presented to the analysts will be in a usable format 

f) (SHSi#REE) Providing operational support as necessary to intelligence analysts on RAS-approved identifiers within the authorized 
number of hops 


on 6. (FS#SI#NF}- Correct! Database management and user interface professionals in Mission Capabilities develop, maintain, and operat 
hat store and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the metadatal 


The correct answer is a). Database management and user interface professionals in Mission Capabilities develop, maintain, and 


a ie 
operate the that store and present BR and PR/TT metadata, and develop algorithms/processes that prepare, optimize, and characterize the 


metadata 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) The Compliance —TORSECRETHICOMINTHNOFORN 12 of 20 
Certification Process 


FRAME ID: 7130 
(U) The Compliance Certification Process 


(U//FOUO) Compliance certification is a mandatory check for all systems handling U.S. 

NEXT FRAME ID: 7140 persomerhlenidata 
(U) Guidelines governing the certification process are maintained by the TD Compliance 
Office 


BACK FRAME ID: 7110 (U) Compliance should be integrated into the development process 


GRAPHIC/AV: 
(U) Image of Technical Character sitting at 
a desk 


FFSHSHINF} (Technical Character): Next we will discuss the compliance certification process used by technical personnel who develop mission 
technologies to include those supporting the BR and PR/TT Programs. Compliance certification is a mandatory check for all systems handling U.S. person 
or FISA data. Guidelines governing the certification process are maintained by the TD Compliance Office. This process supports compliance with the 
applicable laws and authorities and supports the NSA Way. The NSA Way is a unified framework for building large (or small), complex, primarily software 
systems that meet the diverse needs of NSA missions. An important point is that compliance should be integrated into the development process. 
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DATE/PREPARER: SLS Topic 
(U) The Compliance 


Certification Process 


Page Classification 
FGP-SECREHICOMITHINGFORAL 


Screen Number 
13 of 20 


(U) The goal of the compliance certification process is to integrate compliance into the 
development phase 


FRAME ID: 7140 


(U) Following the Compliance Certification Process 


NEXT FRAME ID: 7150 


BACK FRAME ID: 7130 
ALT TAG: 


GRAPHIC/AV: 
(U) Insert Compliance Gates image — if 
image is too large for the window, create a 
separate pop-up to view in full screen. 
Note: Compliance Gates graphic from 
Compliance_Gates_updated 2-28-11.pptx 


Display the screen shot ofl 
when the “To begin the ce 
process...” topic is discussed 


Redisplay the Compliance_Gates.png 
graphic 

FSASHANF) (Technical Character): The goal of the compliance certification process is to integrate compliance into the development phase. The gates 
shown in the compliance process represent distinct requirements that must be satisfied in order to provide reasonable assurance of compliance. The 
architects of the new technology develop engineering documents to support these requirements. The TD certification group reviews the artifacts to verify 
the compliance process requirements are being met. 


FSHSHINF) The compliance certification process begins by registering inIl Il Access the site by typing 1 your web 


browser. Once registration is complete, you will receive a requirements pa 


(U/FOUO) Compliance is an ongoing process. Any change or update to previously certified software requires recertify au compliant. In other 
words, if you develop a modification or upgrade to the software, then you need to register the software modification in to begin the 
recertification process. 


—FORSECRETHSH NOFORN— 
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“CFSHSHANS Formal approval is required for all new and/or different BR and PR/TT systems. Under no circumstances can a change be made to a software 
system (even for testing purposes) without going through the compliance certification (or recertification) process. 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) The Dataflow Process | TOP SECRETICONMINTNGFSORN 14 of 20 


FRAME ID: 7150 
(U) The Dataflow Process 


(U//FOUO) The goal of dataflow governance is to provide reasonable assurance of 
NEXT FRAME ID: 7170 accountability and compliance for NSA mission data as it moves throughout NSA systems 


(U//FOUO) Triggers for entering the dataflow governance process include (but are not 
limited to): 
+ Adding a 
ALT TAG: Replacing an existing repository 
Inserting a process or system into the flow 

GRAPHICS ocr Adding a new mission element 

(U) Image of Technical Character sitting at . . 

a desk Legacy migration 


C-SHSHHNF} (Technical Character): The Collection Strategies and Requirements Center (CSRC) is responsible for dataflow governance, which provides 
reasonable assurance of accountability and compliance for NSA mission data as it moves throughout NSA systems. This is critical to protect the data, and 
when we are talking about volumes of U.S. person data you can understand why this is so important. 


-CFSHSHANF} The process begins by submitting a dataflow request (usually done by the system builder or access owner) for a new dataflow solution. Then 
some level of research is needed to determine the type of request and associated needs. Once the requirements are determined, a new processing 
capability may be developed, or an existing flow may be reconfigured to meet the new requirement. The solution must then be tested and obtain official 
sign-off at which time CSRC authorization to operate would be issued. 


(U/fF OUO) In general. triagers for entering the dataflow governance process include (but are not limited to): 
. 

Replacing an existing repository 

Inserting a process or system into the flow 

Adding a new mission element 

Legacy migration (moving an existing unmanaged flow to a managed flow) 


FSHSHANF) Formal approval is required for all new and/or different BR and PR/TT data flows. Under no circumstances can a change be made to a data 
flow (even for testing purposes) without going through the dataflow governance process. 


U//EQUOQ) To find out more about the dataflow process, please refer to the Dataflow webpage by typing ‘go dataflow’ in your web browser. 
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DATE/PREPARER: SLS Topic 
(U) Knowledge 


Check 3 


Page Classification 
—FOP-SEGREFIECMIFHANOFORN 


Screen Number 
15 of 20 


7. CSHSIANF} The: compliance certification process for new systems is triggered by 


a) (U) Entering a ticket intof 


b) (U/FOUO) Contacting NSA Way Team E 


c) (U//FOUO) Entering the new software or system into | 
d) (U) All of the above 


FRAME ID: 7170 (U) Knowledge Check 3 


NEXT FRAME ID: 7180 


8. (TS/SI//VEMthich of the following is a reason for entering the dataflow governance process? 


e 


BACK FRAME ID: 7150 a 

E b) (U) Replacing an existing repository 
ALT TAG: c) (U) Inserting a process or system into the flow 
GRAPHIC/AV: k (U) Modifying a bulk metadata query 


(U) Moving an existing unmanaged flow to a managed flow 


9. (FSHSIHNF Before an analytic software upgrade is released on a system that handles BR or PR/TT data, 
the developers would need to in order to remain compliant. 


a) (U) contact the CSRC and undergo en 
b) (U) register the software release in nd undergo compliance recertification 
c) (U) obtain OGC approval _———" 

d) (U) register your system with ODOC 


(U) (Technical Character): Let's make a few notes in our travel journal and check to see what you remember from this topic! 


Question UO) Correct! The compliance certification process for new systems is triggered by entering the new software or system in 


ct. The correct answer is c). The compliance certification process for new systems is triggered by entering the new software or system in 


Question 8. (U#FOWQ) Correct! Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 
(U//FOUO) Incorrect. The correct answer is d). Modifying a bulk metadata query is not a reason for entering the dataflow governance process. 


Question 9. (U/-OYS) Correct! Before an analvtic software upgrade is released on a system that handles BR or PR/TT data, the developers would need to 
register the software release in nd undergo compliance recertification in order to remain compliant. 

(U#F OUG) Incorrect. The correc efore an analytic software upgrade is released on a system that handles BR or PR/TT data, the developers 
would need to register the software release in Ce undergo compliance recertification in order to remain compliant. 


FOR SECREFTISHANOFORE 
Page 24 of 30 


DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Practice Scenario 1 FOR-SESGREFYSOMHFFHINGFORN 16 of 20 


FRAME ID: 7180 (U) Practice Scenario 1 


¢FSHSHINF} You are one of the EEE cleared technic ponsible for metadata management 
within NSA's metadata repositories. ries. You are working with other| cleared developers on new query 


NEXT FRAME ID: 7190 processes and tools. YOU mamma set of properly marked recor =Y your team for development 


purposes from the PR/TT metadata. This set of PR/TT metadata records is stored on a physically isolated system 
within NSA’s secure network and is accessible only to the members of your team. Are your actions in 
compliance with the terms of the PR/TT Orders? 


BACK FRAME ID: 7160 (U) Please select the BEST answer: 


AT TAG a) -(FSHSHNF) Yes, because the PR/TT Orders explicitly authorize properly trained technical 
GRAPHIC/AV: personnel to develop and test new technologies to be used with the PR/TT metadata. 


b) (TS#SI#NF) No, because the PR/TT Orders prohibit the use of new query processes against any of 
the PR/TT metadata. 


i = = 
c) {TSH#SHNF} Yes, because tne Er kK: | | metadata records still carry the unique 
markings and software eer the physically isolated system to restrict access to 


those records to DRE BEE 


d) (U) None ofthe above are correct. 


cleared personnel. 


(U) (Technical Character): Now let's practice what we have learned using real-life scenarios. Carefully read the scenario and then select the best answer. 


ANSWER: 


a) 


b) 


c) 


d) 


TS//SI//NF) Incorrect. This statement is accurate, but this is not what makes your actions compliant. The correct answer is c). Yes, because the 
Ned metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to leared personnel. 

TSIHSI/{NF) Jncorrect. The current Court Orders authorize NSA to develop new query processes. The correct answer is c). Yes, because the 
re T metadata records still carry the unique markings and software controls on the physically isolated system to restrict access to 
those records to EE personnel. M 
‘(TSHSHINF)-Correct! The best answer is c). Yes, because the ES eT metadata_records still carry the unique markings and 
software controls on the physically isolated system to restri e records to T cicared personnel. 

(FSHSIHNF) Incorrect. The correct answer is c). Yes, because tne E K / | | metadata r records still carry the unique markings and 
software controls on the physically isolated system to restrict access to those records to HAE personnel. 
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DATE/PREPARER: SLS Topic Page Classification Screen Number 
(U) Practice Scenario 2 —FOP-SESREHIGCMIV-AAINOFORN— 17 of 20 


FRAME ID: 7190 (U) Practice Scenario Ô. mes 
FSHGHENP+ Y ou are a TE cleared developer of contact chaining analytic tools. Your 
management chain has requested a briefing to demonstrate your progress on the latest version of the tool. 
You provide the briefing, which includes screen shots of the tool and query results generated by the tool. Are 
your actions in compliance with the Orders? 


NEXT FRAME ID} T280 (U) Please select the BEST answer: 


(UHFOUS) No, unless all of those on your development team and all those who 
attended your briefing held current LI clearances. 


BACK FRAME ID: 7180 (U) No, because the Court Orders do not permit testing of tools under development using 
real data. 
ALT TAG: (U) Yes, as long as the query results shared during the briefing are never used for 


intelligence analysis purposes. 


US (U) None of the above are correct. 


ANSWER: 

a) (U) Correct! This is the best answer. You cannot provide a demonstration unless all of the individuals who attended the briefing have 
completed the required training and received the necessary accesses. 

b) (U//FOUO) Incorrect. The correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current ic F arances. 

c) (U/FOUO)Incorrect._The correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current clearances. 

d) (U//FOUO) Incorrect. The correct answer is a). No, unless all of those on your development team and all those who attended your briefing held 
current clearances. 
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FRAME ID: 7200 (U) Practice Scenario 3 

{FSHSIZNE) You are one of the TE cleared technical personnel responsible for metadata 
management within NSA’s metadata repositories. You are responsible for the maintenance of backup 
systems and Continuity of Operations (COOP) planning and implementation. You have control over the 
backup tapes that hold PR/TT metadata collected since the inception of the PR/TT authority al In 
accordance with your COOP plans, you know that if a disaster strikes and NSA’s online metadata 
repositories are destroyed, you could use these backup tapes to repopulate the repositories with PR/TT 
metadata. Although the backup tapes contain information older than five years, the processes you would 
employ to repopulate the online analytic metadata repositories would select only metadata collected within 
the last five years. Is your maintenance of backup tapes holding PR/TT metadata collected more than five 
BACK FRAME ID: 7190 years ago in compliance with the terms of the PR/TT Orders? 


NEXT FRAME ID: 7210 


ALT TAG: (U) Please select the BEST answer: 


CaN, (FSHSIHANF)-Yes, because the older-than-five-years PR/TT metadata on the backup tapes 


will never be available for intelligence analysis purposes. 

(FSHSIYNF) Yes, because the PR/TT Orders specifically authorize NSA to maintain backup 
tapes of the PR/TT metadata. 

(FSHSIYNF) No, because the PR/TT Orders mandate the destruction of the PRATT 
metadata no later than five years after its initial collection, with no exception for 
metadata on backup tapes. 

(U) None of the above are correct. 


ANSWER: 

a) (FS#SHĦNF) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. This is different from other authorities, for example FAA 702 does 
not require the destruction of data in the archives. 

b) (FS#SHNF) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 

c) (€SHSIANF) Correct! This is the best answer. No, because the PR/TT Orders mandate the destruction of the PRATT metadata no later than 
five years after its initial collection, with no exception for metadata on backup tapes. 

d) (FS#SIHNF) Incorrect. The correct answer is c). No, because the PR/TT Orders mandate the destruction of the PR/TT metadata no later than five 
years after its initial collection, with no exception for metadata on backup tapes. 
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FRAME ID: 7210 


(U) Now that you have completed this module you should be able to: 
e (FSHSHNF) Identify the various technical roles that support the BR and PR/TT Bulk 
Metadata Programs 
NEXT FRAME ID: 7220 (U) Identify the responsibilities of each of the technical roles 
(U) Recognize key points of the compliance certification process for mission 
systems and data flows 


(FSHSIHNF)-Practice applying BR and PR/TT authorities in real-life scenarios 
applicable to technical personnel 


ALT TAG: 


GRAPHIC/AV: 
(U) Image of Technical Character sitting at f (U//FOU®) If you have questions or wish to find out more, please contact your manager or 


ades any of the following BR or PR/TT points of contact: 
TD Compliance Office website: go td compliance 
OGC email alias: 
OGC website: go GC 


Oversight and Compliance email alias: DL SV42_all 


CFSHSHINF-(Technicel Character): As we stated earlier in the course, the bulk metadata includes sensitive data that must be protected accordingly. By 
nature of the kinds of technical support provided to the BR and PR/TT programs, technical personnel have the authority and unrestricted access to touch 
unminimized/unevaluated (or raw), and very sensitive data (that contains a lot of U.S. person identifiers). Remember, we need to maintain a clear 
distinction between the roles of technical and analytical personnel. All personnel are held to a high standard of integrity, but in your technical role you must 
be particularly cautious because the tools you work with do not provide the same safeguards as those tools used by the analytical personnel. 
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(FSHSIANF) In conclusion, it is your responsibility to keep the BR and PR/TT information within the confines of those who have the proper authorizations to 
touch and view the data. 


(U) Now that we have completed this part of our road trip, you should be able to: 
e (FSHSHNF) Identify the various technical roles that support the BR and PR/TT Bulk Metadata Programs 


e (U) Identify the responsibilities of each of the technical roles 
e (U) Recognize key points of the compliance certification process for mission systems and data flows 
e = =6(FSHSIANB Practice applying BR and PR/TT authorities in real-life scenarios applicable to technical personnel 


(U) You are encouraged to reach out to your management or to any of the points of contact listed here if you have any questions or if you want to find out 
more. 
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FRAME ID; 7220 


(U) PLEASE READ: Important Assessment Information 


(U) You will view the questions in a separate Assessment Questions Document 


NEXT FRAME ID: 7230 
(U) You will enter your responses in a separate QuestionMark online answer sheet 


BACK FRAME ID: 7210 (U) You will have only one attempt to successfully complete the assessment 


ALT TAG: 


GRAPHICIAV: (U) Allow yourself sufficient time (approximately 30 minutes) to complete the assessment 


{(U) To Complete the Assessment: 


e (U) Click the link to open the Assessment Questions Document Comment [SLS1]: Please make this a links that. 
will opeu te Assessment Question pdf Lor 
Analytical Personnel (we will actually connect. the 
link Later). 

« (U) Go to the VUport SumTotal Content Player page, click on the Assessment link, and follow the 


instructions to complete the required exam 


(UHFQOUQ) (OGC Attorney): The final part of your trip will be to successfully complete the assessment for the course. Please be aware that for the 
assessment you will view the questions in a .pdf file and enter your responses in a separate QuestionMark online answer sheet. Please be sure that you 
open the .pdf with the questions first before opening the QuestionMark online answer sheet. You will have one attempt to complete the assessment. Please 
allow yourself sufficient time (approximately 30 minutes) to complete the assessment 


(UASH Please click the Assessment Questions Document link to open the .pdf question file and keep the window open. Then go to the VUport 
SumTotal Content Player page. click on the Assessment link on the left, and follow the instructions to complete the required exam. 
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